΢ÈíÔÚÊý°Ù¸ö×éÖ¯ÄÚÍøÖз¢ÏÖRaspberryRobin

Ðû²¼Ê±¼ä 2022-07-04

1¡¢Î¢Èí͸¶ÔÚÊý°Ù¸ö×éÖ¯µÄÄÚÍøÖз¢ÏÖRaspberry Robin 


¾Ý7ÔÂ2ÈÕ±¨µÀ£¬Î¢Èí×î½üÔÚ¶à¸öÐÐÒµµÄÊý°Ù¼Ò×éÖ¯µÄÄÚÍøÖз¢ÏÖÁËÒ»ÖÖWindowsÈ䳿Raspberry Robin¡£¸Ã¶ñÒâÈí¼þ¿Éͨ¹ý±»Ñ¬È¾µÄUSBÉ豸Á÷´«£¬ÓÚ2021Äê9ÔÂÊ״α»·¢ÏÖ¡£Raspberry Robinͨ¹ý°üÂÞ¶ñÒâ.LNKÎļþµÄUSBÇý¶¯Æ÷ÒÆ¶¯µ½ÐµÄWindowsϵͳ£¬Óû§Ò»µ©Á¬½ÓÁËUSBÉ豸²¢µ¥»÷Á´½Ó£¬¸ÃÈ䳿¾Í»áʹÓÃcmd.exeÉú³ÉÒ»¸ömsiexec½ø³ÌÀ´Æô¶¯´æ´¢ÔÚ±»Ñ¬È¾Çý¶¯Æ÷ÉϵĶñÒâÎļþ¡£Ëü»¹Ê¹ÓÃÁ˼¸¸öºÏ·¨µÄWindows·¨Ê½Ö´ÐжñÒâpayload£ºfodhelper¡¢msiexecºÍodbcconf¡£Î¢ÈíÒѽ«´Ë»î¶¯±ê־Ϊ¸ß·çÏÕ£¬Ä¿Ç°ÉÐ佫Æä¹éÒòÓÚÈκι¥»÷ÍŻ


https://www.bleepingcomputer.com/news/security/microsoft-finds-raspberry-robin-worm-in-hundreds-of-windows-networks/


2¡¢Sharp Boys³ÆÒÑÔÚÒÔÉ«ÁÐÂÃÓÎÍøÕ¾ÇÔÈ¡30ÍòÈËÐÅÏ¢


¾ÝýÌå7ÔÂ1ÈÕ±¨µÀ£¬ºÚ¿ÍÍÅ»ïSharp BoysÉù³ÆÒÑÔÚÒÔÉ«ÁÐÂÃÓÎÍøÕ¾ÇÔÈ¡30ÍòÈËÐÅÏ¢¡£¾ÝϤ£¬ÓÐÁè¼Ý20¸öÂÃÐÐÉç¡¢¾ÆµêºÍ¶È¼Ù´åµÄÍøÕ¾±»ºÚ£¬°üÂÞhotel4u.co.il¡¢hotels.co.il¡¢isrotel.com¡¢minihotel.co.il¡¢trivago.co.ilºÍdanhotels.comµÈ£¬Éæ¼°Óû§µÄÉí·ÝÖ¤ºÅÂë¡¢µØÖ·ºÍÐÅÓÿ¨ÐÅÏ¢µÈ¡£Ä¿Ç°£¬ÒÔÉ«ÁÐÒþ˽±£»¤¾ÖÒѾ­Ã»ÊÕÁËÍйܶà¸öÂÃÐÐÏà¹ØÍøÕ¾µÄ·þÎñÆ÷£¬ÒòΪËûÃǵÄÔËÓªÉÌδÄܽâ¾öµ¼ÖÂй¶Áè¼Ý300000ÈËÐÅÏ¢µÄÄþ¾²ÎÊÌâ¡£


https://www.databreaches.net/iranian-hackers-leak-info-of-over-300000-israelis-from-tourism-sites/


3¡¢³öÊ鹫˾MacmillanÔâµ½ÀÕË÷¹¥»÷ºó¹Ø±ÕÆä»ù´¡ÉèÊ©


ýÌå7ÔÂ2Èճƣ¬ÃÀ¹ú³öÊ鹫˾Âó¿ËÃ×Â×£¨Macmillan£©Ôâµ½ÍøÂç¹¥»÷¡£¹¥»÷·¢ÉúÔÚ6ÔÂ25ÈÕ£¬¸Ã¹«Ë¾³Æ¹¥»÷Õß¼ÓÃÜÁËMacmillanϵͳÉϵIJ¿ÃÅÎļþ£¬Ñо¿ÈËÔ±ÍÆ²âÊÇÀÕË÷¹¥»÷£¬µ«Ä¿Ç°ÉÐδÓкÎÀÕË÷ÍÅ»ïÉù³Æ¶Ô´ËÊÂÂôÁ¦£¬¸Ãʼþ»¹Ó°ÏìÁËÓ¢¹ú·Ö¹«Ë¾Pan Macmillan¡£Ä¿Ç°£¬Macmillan¹Ø±ÕÁËÆäIT»ù´¡ÉèÊ©£¬ÒÔ·ÀÖ¹¶ñÒâÈí¼þÔÚÆäÍøÂçÖÐÁ÷´«£¬²¢¶Ô´ËÊÂÕ¹¿ªÊӲ죬ÒÔ¾¡¿ì»Ö¸´È«ÃæµÄÍøÂ繦Ч¡£


https://securityaffairs.co/wordpress/132792/cyber-crime/macmillan-ransomware-attack.html


4¡¢JenkinsÐû²¼Äþ¾²Í¨¸æ£¬Åû¶Æä¶à¸ö²å¼þÖеÄ34¸ö©¶´


ýÌå7ÔÂ1ÈÕ±¨µÀ³Æ£¬JenkinsÄþ¾²ÍŶÓÐû²¼Á˹ØÓÚ34¸öÄþ¾²Â©¶´µÄͨ¸æ£¬ËüÃÇÓ°ÏìÁËJenkins¿ªÔ´×Ô¶¯»¯·þÎñÆ÷µÄ29¸ö²å¼þ£¬ÆäÖÐ29¸ö©¶´ÈÔÓдýÐÞ¸´¡£ÕâЩ©¶´°üÂÞXSS©¶´¡¢´æ´¢ÐÍXSS©¶´¡¢¿çÕ¾ÇëÇóαÔì(CSRF)©¶´¡¢È¨ÏÞ¼ì²éȱʧ£¬ÒÔ¼°ÒÔ´¿Îı¾ÐÎʽ´æ´¢ÃÜÂë¡¢APIÃÜÔ¿ºÍÁîÅÆµÈ¡£Æ¾¾ÝJenkinsµÄͳ¼ÆÊý¾Ý£¬ÊÜÓ°ÏìµÄ²å¼þ×ܹ²±»°²×°Áè¼Ý22000´Î¡£ÐÒÔ˵ÄÊÇ£¬´ó¶àÊý¸ßÑÏÖØÐԵĩ¶´ÐèÒªÓëÓû§½»»¥²ÅÆø±»ÀûÓá£


https://www.bleepingcomputer.com/news/security/jenkins-discloses-dozens-of-zero-day-bugs-in-multiple-plugins/


5¡¢Kaspersky·¢ÏÖÕë¶ÔIIS·þÎñÆ÷µÄкóÃÅSessionManager


6ÔÂ30ÈÕ£¬KasperskyÐû²¼Á˹ØÓÚкóÃÅSessionManagerµÄ·ÖÎö³ÂËß¡£Ñо¿ÈËÔ±³Æ£¬¸ÃºóÃÅ×Ô2021Äê3ÔÂÒÔÀ´Ò»Ö±±»ÓÃÓÚÕë¶ÔMicrosoft IIS·þÎñÆ÷µÄ¹¥»÷¡£ËüÓÉC++±àд£¬ÀûÓÃExchange·þÎñÆ÷ÖеÄProxyLogon©¶´Î±×°³ÉInternetÐÅÏ¢·þÎñ(IIS)µÄÄ£¿é£¬¾ßÓжÁÈ¡¡¢Ð´ÈëºÍɾ³ýÈÎÒâÎļþµÄ¹¦Ð§£¬¿É´Ó·þÎñÆ÷Ö´Ðжþ½øÖÆÎļþ£¬²¢ÓëÍøÂçÖÐµÄÆäËü¶Ëµã½¨Á¢Í¨ÐÅ¡£´ËÍ⣬Æä³äµ±ÁËÒ»¸öÃØÃÜͨµÀ£¬ÓÃÓÚ½øÐÐÕì²ì¡¢ÊÕ¼¯ÄÚ´æÃÜÂ룬²¢ÌṩÆäËü¹¤¾ß£¬ÈçMimikatzµÈ¡£


https://securelist.com/the-sessionmanager-iis-backdoor/106868/


6¡¢ESETÐû²¼Ã°³ä¼ÓÄôó˰Îñ»ú¹¹µÄµöÓã¹¥»÷»î¶¯µÄ³ÂËß


ESETÔÚ7ÔÂ1ÈÕÐû²¼ÁËð³ä¼ÓÄôó˰Îñ»ú¹¹µÄµöÓã¹¥»÷»î¶¯µÄ·ÖÎö³ÂËß¡£»î¶¯ÖÐʹÓõĵöÓãÓʼþÉù³ÆÀ´×Ô¼ÓÄôó˰Îñ¾Ö(CRA)£¬²¢ÔÊÐí¿ÉÍË˰½ü500¼ÓÔª¡£µ±Ä¿±êµã»÷°´Å¥Interac e-Transfer Autodepositʱ£¬½«±»´ÓÍйÜÔÚistandyjeno[.]huµÄ¶ñÒâÁ´½ÓÖØ¶¨Ïòµ½ÍйÜÔÚoraclehomes.comµÄ¶ñÒâ×ÓÎļþ¼Ðcra_ca_service¡£Ö®ºó£¬µöÓãÍøÕ¾»áÓÕʹĿ±êÊäÈë¸öÈËÐÅÏ¢ºÍÐÅÓÿ¨ÐÅÏ¢£¬È»ºóÔÙ½«ÆäÖØ¶¨Ïòµ½ºÏ·¨µÄCRAÍøÕ¾¡£


https://www.welivesecurity.com/2022/07/01/phishing-scam-posing-canadian-tax-agency-canada-day/